← Back

CVE-2009-4358

nvd nist
Published: Dec 20, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.7
Vector
AV:L/AC:M/Au:N/C:C/I:N/A:N
Exploitability: 3.4 / Impact: 6.9
Source: NVD

Description

freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses insecure permissions in its working directory (/var/db/freebsd-update by default), which allows local users to read copies of sensitive files after a (1) freebsd-update fetch (fetch) or (2) freebsd-update upgrade (upgrade) operation.

Affected (5)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 6.3
Version 6.4
Version 7.1
Version 7.2
Version 8.0

Related CWEs

References (6)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.